CVE-2026-92948
## Summary On Node.js 24 and newer, `vm2` can expose the host `node:test` module to sandboxed `NodeVM` code when the embedder explicitly allows the `node:test` builtin. Sandbox code can reach that module through `require('node:node:test')` and call `run()` with attacker-controlled `execArgv`. `node:test.run()` starts a separate Node process for process-isolated test execution and forwards the supplied `execArgv` values to that process. Supplying `--eval=<JavaScript>` therefore executes arbitrary JavaScript in an unrestricted host Node process, outside the `NodeVM` sandbox. The PoC confirms that direct sandbox imports of `fs`, `child_process`, `module`, and `process` remain denied before the spawned process imports host `fs` and writes a harmless marker. ## Affected versions and environment - Package: `vm2` - Affected versions: `>=3.9.6, <=3.11.5` - Latest reproduced version: `3.11.5` - Reproduced runtime: Node.js `v24.18.0` - Exact path is not present on Node.js 22 because `module.builtinModules` does not expose the scheme-only `node:test` entry there - Configuration prerequisite: ```js require: { builtin: ['node:test'], external: false } ``` The lower version boundary was tested directly: `[email protected]` blocks `require('node:node:test')`, while `[email protected]` permits the exploit path. Representative releases through `3.11.5` were also reproduced. ## Root cause The issue is a combination of builtin admission, generic host passthrough, and prefix normalization: 1. On Node.js 24+, `module.builtinModules` includes the scheme-only key `node:test`. 2. `lib/builtin.js` builds `BUILTIN_MODULES` from that array. The family-based `DANGEROUS_BUILTINS` protection does not include `test`, so `node:test` remains eligible. 3. When the embedder explicitly allows `node:test`, `addDefaultBuiltin()` stores it through the generic loader: ```js builtins.set(key, special ? special : vm => vm.readonly(hostRequire(key))); ``` 4. In `lib/setup-node-sandbox.js`, `requireImpl()` st
Properties
- severity
- critical
- summary
- vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
- cvss_score
- 9.9
- retrieved_at
- 2026-10-01T19:14:01+00:00
- ghsa_published
- 2026-10-01T15:41:31Z
- source_url
- https://github.com/advisories/GHSA-qhwx-74w5-xhxq
- ghsa_updated
- 2026-10-01T15:41:32Z
- ghsa_id
- GHSA-qhwx-74w5-xhxq
- last_source
- GitHub Advisory Database
- cve_id
- CVE-2026-92948
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- signal_observed_at
- 2026-10-01T19:14:01+00:00
- is_ghsa_only
- false
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph